USN-7033-1: Intel Microcode vulnerabilities
It was discovered that some Intel(R) Processors did not properly restrict access to the Running Average Power Limit (RAPL) interface. This may allow a local privileged attacker to obtain sensitive information. (CVE-2024-23984) It was discovered that some Intel(R) Processors did not properly implement finite state machines (FSMs) in hardware logic. This may allow a local privileged attacker to cause a denial of service (system crash). (CVE-2024-24968)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7033-1?
The severity of USN-7033-1 is considered to be high due to the potential for local privileged attackers to access sensitive information.
How do I fix USN-7033-1?
To fix USN-7033-1, you should update the intel-microcode package to the specified version for your Ubuntu distribution.
Which versions of Ubuntu are affected by USN-7033-1?
USN-7033-1 affects Ubuntu versions 16.04, 18.04, 20.04, 22.04, and 24.04.
What components are involved in the USN-7033-1 vulnerability?
The USN-7033-1 vulnerability involves issues with the Running Average Power Limit (RAPL) interface on certain Intel processors.
Is there a specific package to upgrade for USN-7033-1?
Yes, you need to upgrade the intel-microcode package to the appropriate version based on your Ubuntu release.